基于特征正则对抗训练的视觉跟踪对抗鲁棒性提升方法

武哲纬 ,  余瑞龙 ,  刘启和 ,  吴春江 ,  叶飞 ,  周世杰

电子科技大学学报 ›› 2026, Vol. 55 ›› Issue (2) : 252 -262.

PDF (1695KB)
电子科技大学学报 ›› 2026, Vol. 55 ›› Issue (2) : 252 -262. DOI: 10.12178/1001-0548.2024351
计算机工程与应用

基于特征正则对抗训练的视觉跟踪对抗鲁棒性提升方法

作者信息 +

Improving adversarial robustness of visual trackers via feature regularized adversarial training

Author information +
文章历史 +
PDF (1735K)

摘要

该文首先基于对抗特征与原始特征在不同卷积尺度下产生分离这一经验观察,提出了特征正则化损失以使二者在特征空间中实现对齐。其次,针对目标跟踪任务的双图像输入特性,创新性地设计了适配深度跟踪网络的对抗训练框架。该框架利用特征正则化损失指导对抗样本生成,有效引导网络在对抗训练中学习鲁棒特征表示,从而显著提升目标跟踪模型的对抗鲁棒性。最后,在公开数据集上的对比实验证明,提出的方法能够在自适应攻击场景下获得最优的性能,同时能够在异构跟踪器间实现有效迁移,且在干净样本上保持有限的精度损失。

Abstract

Visual object tracking (VOT), as a crucial downstream task in computer vision, has consistently garnered significant attention due to its widespread applications. In recent years, adversarial attack methods for VOT have emerged, which disrupt tracker predictions by injecting adversarial perturbations into input data. However, corresponding adversarial defense approaches remain scarce and suffer from multiple limitations: inadequate defense performance against adaptive attacks, excessive computational overhead introduced by preprocessing modules, and poor transferability across heterogeneous trackers. To address these challenges, this paper proposes a feature regularization loss based on the empirical observation that adversarial features and original features exhibit divergence across different convolutional scales, aiming to achieve feature space alignment between them. Second, considering the dual-image input characteristics of visual tracking tasks, an adversarial training framework tailored for visual tracker is designed. This framework effectively guides the network to learn robust feature representations by leveraging the feature regularization loss, thereby enhancing the adversarial robustness of the tracker. Finally, comparative experiments on public benchmarks demonstrate that our method achieves state-of-the-art performance under adaptive attack scenarios while maintaining limited accuracy degradation on clean samples. Notably, the proposed approach exhibits superior transferability across heterogeneous tracking architectures compared to existing defense methods.

关键词

视觉单目标跟踪 / 对抗防御技术 / 对抗训练 / 计算机视觉

Key words

visual single object tracking / adversarial defense / adversarial training / computer vison

引用本文

引用格式 ▾
武哲纬,余瑞龙,刘启和,吴春江,叶飞,周世杰. 基于特征正则对抗训练的视觉跟踪对抗鲁棒性提升方法[J]. 电子科技大学学报, 2026, 55(2): 252-262 DOI:10.12178/1001-0548.2024351

登录浏览全文

4963

注册一个新账户 忘记密码

参考文献

[1]

LI P X, JIN J Y. Time3D: End—to—end joint monocular 3D object detection and tracking for autonomous driving[C]// Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. New York: IEEE, 2022: 3875-3884.

[2]

LUO C X, YANG X D, YUILLE A. Exploring simple 3D multi—object tracking for autonomous driving[C]// Proceedings of the IEEE/CVF International Conference on Computer Vision. New York: IEEE, 2021: 10468-10477.

[3]

SANDOVAL L A C. Low cost object tracking by computer vision using 8 bits communication with a viper robot[C]// Proceedings of the 8th International Conference on Control and Robotics Engineering. New York: IEEE, 2023: 232-237.

[4]

GOODFELLOW I J, SHLENS J, SZEGEDY C. Explaining and harnessing adversarial examples[EB/OL]. [ 2024—04—14]. https://www.researchgate.net/publication/269935591_Explaining_and_Harnessing_Adversarial_Examples.

[5]

YAN B, WANG D, LU H C, et al. Cooling—shrinking attack: Blinding the tracker with imperceptible noises[C]// Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. [S. l.]: IEEE, 2020: 990-999.

[6]

SUTTAPAK W, ZHANG J F, ZHANG L Q. Diminishing—feature attack: The adversarial infiltration on visual tracking[J]. Neurocomputing, 2022, 509: 21-33.

[7]

JIA S, SONG Y B, MA C, et al. IoU attack: Towards temporally coherent black—box adversarial attack for visual object tracking[C]// Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. [S. l.]: IEEE, 2021: 6709-6718.

[8]

LIU S A, CHEN Z Y, LI W, et al. Efficient universal shuffle attack for visual object tracking[C]// Proceedings of the ICASSP 2022 — 2022 IEEE International Conference on Acoustics, Speech and Signal Processing. New York: IEEE, 2022: 2739-2743.

[9]

GUO Q, XIE X F, JUEFEI—XU F, et al. SPARK: spatial—aware online incremental attack against visual tracking[M]// Computer Vision — ECCV 2020. Cham: Springer International Publishing, 2020: 202-219.

[10]

WU Z W, YU R L, LIU Q H, et al. Enhancing tracking robustness with auxiliary adversarial defense networks[M]// Computer Vision — ECCV 2024. Cham: Springer Nature Switzerland, 2024: 198-214.

[11]

CHEN J L, REN X H, GUO Q, et al. LRR: Language—driven resamplable continuous representation against adversarial tracking attacks[EB/OL]. [ 2024—04—15]. https://arxiv.org/abs/2404.06247.

[12]

TRAMER F, CARLINI N, BRENDEL W, et al. On adaptive attacks to adversarial example defenses[J]. Advances in Neural Information Processing Systems, 2020, 33: 1633-1645.

[13]

CARLINI N, WAGNER D. Adversarial examples are not easily detected: Bypassing ten detection methods[C]// Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security. New York: ACM, 2017: 3-14.

[14]

BAI T, LUO J Q, ZHAO J, et al. Recent advances in adversarial training for adversarial robustness[EB/OL]. [ 2024—04—20]. https://arxiv.org/abs/2102.01356.

[15]

ZHANG H C, WANG J Y. Towards adversarially robust object detection[C]// Proceedings of the IEEE/CVF International Conference on Computer Vision. New York: IEEE, 2019: 421-430.

[16]

BERTINETTO L, VALMADRE J, HENRIQUES J F, et al. Fully—convolutional Siamese networks for object tracking[M]//HUA G, JÉGOU H, eds. Computer Vision — ECCV 2016 Workshops. Cham: Springer International Publishing, 2016: 850-865.

[17]

LI B, YAN J J, WU W, et al. High performance visual tracking with Siamese region proposal network[C]// Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. New York: IEEE, 2018: 8971-8980.

[18]

LI B, WU W, WANG Q, et al. SiamRPN++: Evolution of Siamese visual tracking with very deep networks[C]// Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. IEEE, 2019: 4282-4291.

[19]

WANG Q, ZHANG L, BERTINETTO L, et al. Fast online object tracking and segmentation: A unifying approach[C]// Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. New York: IEEE, 2019: 1328-1338.

[20]

CHEN X, YAN B, ZHU J, et al. Transformer tracking[C]// Proceedings of the IEEE/CVF Conference On Computer Vision and Pattern Recognition. [S.l. ]: IEEE, 2021: 8126-8135.

[21]

XING D T, EVANGELIOU N, TSOUKALAS A, et al. Siamese transformer pyramid networks for real—time UAV tracking[C]// Proceedings of the IEEE/CVF Winter Conference on Applications of Computer Vision. New York: IEEE, 2022: 1898-1907.

[22]

JIA S, MA C, SONG Y B, et al. Robust tracking against adversarial attacks[M]//VEDALDI A, BISCHOF H, BROX T, et al, eds. Computer Vision — ECCV 2020. Cham: Springer International Publishing, 2020: 69-84.

[23]

YU R L, WU Z W, LIU Q H, et al. CMDN: Pre—trained visual representations boost adversarial robustness for UAV tracking[J]. Drones, 2024, 8(11): 607.

[24]

SZEGEDY C, ZAREMBA W, SUTSKEVER I, et al. Intriguing properties of neural networks[EB/OL]. [ 2024—05—2]. https://www.researchgate.net/publication/259440613_Intriguing_properties_of_neural_networks.

[25]

MIYATO T, KATAOKA T, KOYAMA M, et al. Spectral normalization for generative adversarial networks[EB/OL]. [22024—05—10]. https://arxiv.org/abs/1802.05957.

[26]

WU Y, LIM J, YANG M H. Object tracking benchmark[J]. IEEE Transactions on Pattern Analysis and Machine Intelligence, 2015, 37(9): 1834-1848.

[27]

KRISTAN M, LEONARDIS A, MATAS J, et al. The sixth visual object tracking VOT2018 challenge results[C]// Computer Vision — ECCV 2018 Workshops. Cham: Springer International Publishing, 2019: 3-53.

[28]

FAN H, LIN L T, YANG F, et al. LaSOT: A high—quality benchmark for large—scale single object tracking[C]// Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. New York: IEEE, 2019: 5369-5378.

[29]

ZHANG H Y, YU Y D, JIAO J T, et al. Theoretically principled trade—off between robustness and accuracy[EB/OL]. [ 2024—05—20]. https://arxiv.org/abs/1901.08573.

[30]

RICE L, WONG E, KOLTER Z. Overfitting in adversarially robust deep learning[C]// International Conference on Machine Learning. [S.l.]: PMLR, 2020: 8093-8104.

基金资助

国家自然科学基金(62272089)

四川省自然科学基金(2025ZNSFSC0510)

厅市共建智能终端四川省重点实验室开放课题(SCITLAB-30003)

AI Summary AI Mindmap
PDF (1695KB)

239

访问

0

被引

详细

导航
相关文章

AI思维导图

/